Langflow 是一个用于构建和部署 AI 驱动智能体(agents)和工作流的工具。在版本 1.6.8 至 1.9.1 之间,Langflow 对项目中作用域的 MCP(Model Context Protocol)连接中的项目标识符进行了身份验证,但未对提供给 的资源 URI 实施授权控制。 函数将攻击者可控制的 URI 转发给 ,后者解析出 flow_id 和文件名,并调用 ,但在此过程中并未验证该 flow 是否属于已认证用户或当前项目。因此,任何有权访问项目中作用域 MCP 端点的用户,均可请求获取其他
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| langflow-ai | langflow | >= 1.6.8, <= 1.9.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105697 | 9.9 CRITICAL | Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configurati |
| CVE-2026-105740 | 9.9 CRITICAL | Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary O |
| CVE-2026-105741 | 7.1 HIGH | Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write |
| CVE-2026-105698 | 5.4 MEDIUM | Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_i |
No comments yet